project-migration
Warn
Audited by Socket on May 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly coherent for project migration and uses plausible same-org repos for blueprints/state, with no clear credential theft or exfiltration. However, it includes transitive skill installation via `npx skills add`, expanding trust and permissions beyond basic migration, so the overall risk is medium rather than benign.
Confidence: 87%Severity: 56%
Audit Metadata